Description


Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.

Related CPE's


Could not find any relations

Weaknesses



CWE-863

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

8.5 · High

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Received

Published

2026-01-02T17:16:23.710

5 hours ago

Last modified

2026-01-02T17:16:23.710

5 hours ago